Secure Boot is not a normal Windows switch, so it can feel hidden when a game, app, or Windows requirement says it needs to be on. The setting lives in your PC's UEFI firmware, and Windows Settings can take you straight there without guessing the boot key.
Start with the Windows route, then use the brand-specific steps if your firmware menu looks different.
1. Open UEFI Firmware From Windows Settings
- 1.Open Settings.
- 2.Go to System > Recovery.
- 3.Under Advanced startup, select Restart now.
- 4.Choose Troubleshoot > Advanced options > UEFI Firmware Settings.
- 5.Select Restart.
- 6.In the firmware menu, open Boot, Security, or Authentication.
- 7.Before you change the boot mode, open System Information (msinfo32) and check BIOS Mode, then open Disk Management and check the system disk's partition style. Windows installed in Legacy mode on an MBR disk can fail to start after the switch, so back up your data and convert the disk first with the built-in MBR2GPT tool.
- 8.Change Legacy or CSM boot mode to UEFI, set Secure Boot to Enabled, then save changes and exit.
2. Enter BIOS With the Startup Key
- 1.Restart or power on the PC.
- 2.Press the BIOS key during startup. Use F1, F2, F12, or Esc.
- 3.Open Security, Boot, or Authentication.
- 4.Find Secure Boot and set it to Enabled.
- 5.Save changes and exit.
If the startup key misses the timing window, use the Windows Settings route in section 1.
3. Turn On Secure Boot on Dell PCs
- 1.Turn on or restart the Dell PC.
- 2.At the Dell logo, repeatedly tap F2.
- 3.On Dell systems manufactured after 2021, go to Boot Configuration, set boot mode to UEFI only, enable Secure Boot, click Apply Changes, and exit BIOS.
- 4.On Dell systems manufactured before 2021, expand General > Boot Sequence, set Boot List Option to UEFI, open Secure Boot > System Information, check Secure Boot Enable, click Apply, and exit BIOS.
4. Find Secure Boot on HP and Lenovo
On HP PCs, the menu depends on the device type. On HP consumer notebooks, press F10 to open BIOS Setup, go to System Configuration > Boot Options, set Legacy Support to Disabled if it is listed, then set Secure Boot to Enabled and save changes. On HP commercial notebooks and workstations, open BIOS Setup (F10), select the Security tab, then Secure Boot Configuration, and select the Secure Boot box. On HP desktops, tap F10 at startup, select Security > Secure Boot Configuration, press F10 at the message, set Legacy Support to Disable and Secure Boot to Enable, then press F10 to accept the changes. From the HP startup menu, press Esc for Startup Menu, then press F10 for BIOS Setup.
On Lenovo ThinkPad, ThinkStation, and ThinkCentre systems, tap F1 at the Lenovo or Think logo, then use Security > Secure Boot, enable it, and press F10 to save and exit. On Lenovo Yoga and IdeaPad-style systems, press F2 at the Lenovo logo or use the Novo Button menu, choose UEFI/BIOS Setup, then enable Secure Boot under Security > Secure Boot.
5. Fix a Grayed Out Secure Boot Option
This fixes firmware menus that show Secure Boot but block the switch.
- 1.Change Legacy or CSM boot mode to UEFI.
- 2.On Acer notebooks and desktops, open Security > Set Supervisor Password when Secure Boot is unavailable or grayed out.
- 3.Create the supervisor password, then return to Secure Boot.
- 4.Set Secure Boot to Enabled.
- 5.Press F10, select Yes, and restart.
6. Enable Secure Boot on ASUS MSI and GIGABYTE
- 1.On ASUS notebooks, all-in-ones, and gaming handhelds, enter BIOS, press F7 or click Advanced Mode, then go to Security > Secure Boot. Set Secure Boot Control to Enabled, press F10, click Ok, and restart.
- 2.On ASUS desktops, enter BIOS, press F7 or click Advanced Mode, then go to Boot > Secure Boot. Set OS Type to Windows UEFI mode, press F10, click Ok, and restart.
- 3.On ASUS motherboards, power on and press Delete to enter BIOS Advanced Mode. Go to Boot > Secure Boot, set OS Type to Windows UEFI mode, confirm Secure Boot keys are present, save, and exit.
- 4.On MSI AM4 motherboards, confirm the system disk is GPT and BIOS Mode is UEFI, then go to Settings > Advanced > Windows OS Configuration and set BIOS CSM/UEFI Mode to UEFI. Open the Secure Boot menu, enable Secure Boot, and press F10 to save and reboot.
- 5.On MSI laptops, restart and press Delete at the MSI logo, then go to Security > Secure Boot > Enable. Press F10 to save and restart. If the laptop shows a Secure Boot Violation message and will not start Windows, MSI's recovery workflow comes first: set Security > Secure Boot > Disable and press F10 to reach Windows, format a USB flash drive as FAT32, extract MSI's Secure Boot Violation Tool onto it, press F11 at the MSI logo and boot from that drive, then re-enter BIOS and set Security > Secure Boot > Enable.
- 6.On GIGABYTE AM4 or sTRX4 motherboards, confirm the disk is GPT and Windows BIOS Mode is UEFI, enter BIOS with Delete, go to Advanced Mode > Boot > CSM Support, and choose Disabled. Then open Advanced Mode > Boot > Secure Boot > Secure Boot Mode, choose Custom, install factory defaults when prompted, and confirm Secure Boot shows Active after re-entering BIOS.
MSI says Secure Boot and TPM 2.0 are enabled by default on more recent platforms such as X870, X670, B850, and B650, and GIGABYTE says they are typically enabled by default on newer AM5 and sTR5 systems running Windows 11. Defaults still vary by board and configuration, so check Secure Boot State in System Information or in the firmware menu before assuming it is already on.
7. Restore Secure Boot Keys When Status Is Not Active
- 1.In BIOS or UEFI, open the Secure Boot page.
- 2.Use the firmware Reset or Defaults option when Secure Boot keys or settings block activation.
- 3.Return to the Secure Boot setting, set it to Enabled, then save changes and exit.
- 4.On Lenovo ThinkPad systems in Setup Mode, click Restore Factory Keys to return Platform Mode to User Mode, then set Secure Boot to Enabled.
- 5.On ASUS devices showing Secure Boot as Not Active, set Secure Boot Control to Enabled, then use Key Management > Reset To Setup Mode > Yes > Restore Factory Keys > Yes, then save and exit.
- 6.On ASUS desktop UEFI, set Secure Boot Mode to Custom, then use Key Management > Clear Secure Boot Keys > Yes > Install Default Secure Boot Keys, then save and exit.
8. Use Surface UEFI on Microsoft Surface
On supported Surface devices, shut down, wait about 10 seconds, hold Volume-Up, press and release Power, then keep holding Volume-Up until Surface UEFI appears. Open Security, turn Secure Boot on or change its configuration, then use Exit > Restart now.
You can also open Surface UEFI from Windows through Start > Settings > System > Recovery > Restart Now > Troubleshoot > Advanced Options > UEFI Firmware Settings > Restart. Most people get the 2026 Surface Secure Boot certificates automatically through Windows Update with no action required. If you want to deploy them manually, check Microsoft's list of supported Surface models and minimum UEFI versions first, and have your BitLocker recovery key ready, because the change triggers a BitLocker recovery prompt. On a supported device, open Security, select Change Configuration under Secure Boot, select Microsoft only, choose OK, then use Exit > Restart now.
9. Check Whether Work Manages Secure Boot
This identifies PCs where your organization controls Secure Boot certificates or UEFI settings.
- 1.For IT-managed Windows devices, check whether your organization uses Microsoft Intune, Group Policy, registry deployment, or Surface DFCI for Secure Boot certificate deployment or UEFI management.
- 2.Use the local firmware menu when Secure Boot is off on a consumer PC; those management tools do not replace the firmware Secure Boot toggle.
- 3.Ask your workplace IT admin before changing Secure Boot or UEFI settings on a managed computer.
Frequently Asked Questions
Can I enable Secure Boot from inside Windows?
Windows Settings can restart the PC into UEFI firmware. The Secure Boot switch itself is changed inside the firmware menu.
Which BIOS key opens Secure Boot settings?
Common startup keys include F1, F2, F12, Esc, and Delete. Dell uses F2, HP uses Esc then F10 from the startup menu, many Lenovo Think systems use F1, and many ASUS, MSI, GIGABYTE, and Acer desktops use Delete.
Why is Secure Boot grayed out?
The PC can be in Legacy or CSM mode, the Secure Boot keys can be inconsistent, or an Acer system can require a supervisor password before the setting unlocks.
Is msconfig Safe boot the same as Secure Boot?
No. msconfig Safe boot starts Windows in Safe Mode. It does not enable UEFI Secure Boot.











